Re: Security team successfully cracks SSL using 200 PS3's and MD5

2009-01-05 Thread Jason Uhlenkott
On Fri, Jan 02, 2009 at 15:33:05 -0600, Joe Greco wrote: > This would seem to point out some critical shortcomings in the current SSL > system; these shortcomings are not necessarily technological, but rather > social/psychological. We need the ability for Tom, Dick, or Harry to be > able to crank

Re: Security team successfully cracks SSL using 200 PS3's and MD5

2009-01-05 Thread Jason Uhlenkott
On Tue, Jan 06, 2009 at 06:09:34 +0900, Randy Bush wrote: > to use your example, the contractor who serves dns for www.bank.example > could insert a cert and then fake the web site having (a child of) that > cert. whereas, if the site had its cert a descendant of the ca for all > banks, this at